CVE-2026-97735: Itflow

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

Affected products

  • Itflow Itflow: before 26.08 (fixed in 26.08)

Published 2026-09-25. Last modified 2026-09-30.